mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
synced 2026-08-30 15:43:08 -04:00
scsi: qla2xxx: Bound i2c->length in I2C bsg handlers
struct qla_i2c_access carries a 16-bit length field alongside a fixed
64-byte buffer:
struct qla_i2c_access {
uint16_t device, offset, option, length;
uint8_t buffer[0x40];
} __packed;
qla2x00_write_i2c() and qla2x00_read_i2c() use the user-supplied
i2c->length without any bounds check. i2c is overlaid on a 256-byte
on-stack buffer and sfp is a 256-byte DMA-pool buffer, so a length up to
65535 overruns both:
- write: memcpy(sfp, i2c->buffer, i2c->length) over-reads the stack and
over-writes the sfp heap buffer, and qla2x00_write_sfp() then DMAs
i2c->length bytes out of the 256-byte buffer.
- read: qla2x00_read_sfp() DMAs i2c->length bytes into the 256-byte sfp,
then memcpy(i2c->buffer, sfp, i2c->length) overflows the 64-byte
buffer inside the on-stack array.
A caller holding CAP_SYS_RAWIO can use this to corrupt the heap and the
kernel stack. Reject requests whose length exceeds the buffer before any
copy or DMA transfer in both handlers.
Fixes: 9ebb5d9c69 ("[SCSI] qla2xxx: Add I2C BSG interface.")
Cc: stable@vger.kernel.org
Reported-by: Sashiko <sashiko-dev@google.com>
Signed-off-by: Nilesh Javali <njavali@marvell.com>
Link: https://patch.msgid.link/20260730155838.2119230-33-njavali@marvell.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
This commit is contained in:
committed by
Martin K. Petersen (Oracle)
parent
b47d4a1547
commit
0918ee2c0e
@@ -2175,6 +2175,12 @@ qla2x00_write_i2c(struct bsg_job *bsg_job)
|
||||
sg_copy_to_buffer(bsg_job->request_payload.sg_list,
|
||||
bsg_job->request_payload.sg_cnt, i2c, sizeof(*i2c));
|
||||
|
||||
if (i2c->length > sizeof(i2c->buffer)) {
|
||||
bsg_reply->reply_data.vendor_reply.vendor_rsp[0] =
|
||||
EXT_STATUS_INVALID_PARAM;
|
||||
goto dealloc;
|
||||
}
|
||||
|
||||
memcpy(sfp, i2c->buffer, i2c->length);
|
||||
rval = qla2x00_write_sfp(vha, sfp_dma, sfp,
|
||||
i2c->device, i2c->offset, i2c->length, i2c->option);
|
||||
@@ -2221,6 +2227,12 @@ qla2x00_read_i2c(struct bsg_job *bsg_job)
|
||||
sg_copy_to_buffer(bsg_job->request_payload.sg_list,
|
||||
bsg_job->request_payload.sg_cnt, i2c, sizeof(*i2c));
|
||||
|
||||
if (i2c->length > sizeof(i2c->buffer)) {
|
||||
bsg_reply->reply_data.vendor_reply.vendor_rsp[0] =
|
||||
EXT_STATUS_INVALID_PARAM;
|
||||
goto dealloc;
|
||||
}
|
||||
|
||||
rval = qla2x00_read_sfp(vha, sfp_dma, sfp,
|
||||
i2c->device, i2c->offset, i2c->length, i2c->option);
|
||||
|
||||
|
||||
Reference in New Issue
Block a user